Founding Security Engineer

New York, NY
Full Time
Information Technology
Mid Level

Role: Founding Security Engineer 

HRforGrowth® is engaged as the talent acquisition partner to conduct this search on behalf of a client organization that is hiring for this role. HRforGrowth is not the employer for this position. HRforGrowth identifies, evaluates, and presents top-tier candidates through its global talent acquisition practice; all employment decisions — including final selection, offer terms, compensation, and conditions of employment — are made solely by the hiring organization.

Our Client is seeking a Founding Security Engineer to own both internal and customer-facing security at a cloud infrastructure company where security is core to the product.

This is a software engineering role first. The ideal candidate will be a strong software engineer who enjoys thinking deeply about security in and around the cloud and is excited to build systems that protect hundreds of customers' production infrastructure.

This is a rare opportunity to become the first dedicated security hire at a company whose platform operates directly inside customers' AWS, GCP, and Azure environments. The role offers the opportunity to solve high-stakes, deeply technical security challenges, work directly with leading customers, shape the security roadmap from the ground up, and build security capabilities that allow engineering teams to confidently manage sensitive infrastructure.

.

.Location: New York, NY
Job Type: Full-Time
Compensation: $220,000 – $320,000 per year
Visa Sponsorship: Open to H-1B transfers
Relocation: Relocation support available
PTO: 30 days per year
 

Key Responsibilities

  • Found and lead the Secure Engineering function, establishing the internal security roadmap and championing security best practices across a flat engineering organization of approximately 20 engineers.
  • Build and ship customer-facing security products that improve the security posture of companies running on the platform.
  • Write production-quality Go code to harden multi-cloud infrastructure across AWS, GCP, and Azure.
  • Secure Kubernetes clusters deployed across hundreds of customer accounts.
  • Own cloud and container security end-to-end, including IAM, network security, secret management, workload isolation, and security logging.
  • Design and implement security systems that protect customer production infrastructure across multiple cloud environments.
  • Work directly with customers' security engineering teams to build trust, understand security requirements, and ensure managed infrastructure meets or exceeds their security standards.
  • Partner closely with engineering teams to integrate secure development practices throughout the software development lifecycle.
  • Identify vulnerabilities, security risks, and infrastructure weaknesses and develop practical technical solutions to address them.
  • Establish security standards, processes, and engineering practices as the company's first dedicated security engineer.
  • Balance internal security needs with customer-facing security requirements while maintaining a high engineering standard.

Required Qualifications

Experience
  • Minimum 4+ years of experience as an infrastructure or platform engineer.
  • Currently working as a software engineer writing production application code, rather than exclusively in a DevOps or SRE capacity.
  • Experience building or contributing to core infrastructure at an infrastructure-focused company such as a PaaS, IaaS, cloud platform, or internal developer platform company.
  • Alternatively, experience at a company with an exceptionally high engineering bar, such as Stripe, Ramp, or Databricks.
  • Demonstrated experience working on technically complex infrastructure and security challenges.

Technical Skills
  • Strong proficiency in Go and experience writing production software.
  • Hands-on experience with cloud and container security, including areas such as AWS IAM, Kubernetes, security logging, secret management, and network security.
  • Application security experience, including authentication/authorization, vulnerability research, and secure software development practices.
  • Experience working with at least one major cloud platform: AWS, GCP, or Azure.
  • Experience securing or operating infrastructure across multiple cloud environments.
  • Strong understanding of Kubernetes and containerized infrastructure.
  • Experience with infrastructure and security technologies such as Terraform, Docker, IAM, and SQL.

Candidate Profile
  • Strong software engineering fundamentals with the ability to build production systems rather than simply configure infrastructure.
  • Ability to operate as the first dedicated security engineer and take ownership of the security function from the ground up.
  • Comfortable working directly with customers and their security teams.
  • Strong technical judgment and the ability to make practical security and engineering tradeoffs.
  • Comfortable operating in a small, fast-moving engineering organization with significant autonomy.

Dealbreakers

The following are critical requirements for this position:
  • Candidates must currently write production application code as a software engineer.
  • Pure DevOps/SRE profiles without significant software engineering experience will not be considered.
  • Candidates whose experience primarily consists of infrastructure setup without writing software to manage or secure that infrastructure are not a fit.
  • Resumes heavily focused on tools and buzzwords such as Helm, Terraform, or CI/CD without demonstrated depth in software engineering, infrastructure, or security are not a fit.
  • Contractors or consultants are not preferred for this role.
  • Candidates from non-infrastructure companies generally will not be considered unless they come from an organization with an exceptionally high engineering bar.

Preferred Qualifications
  • Experience serving as a founding security engineer or security-focused engineer.
  • Experience building customer-facing security products or security features.
  • Experience establishing security practices and programs from the ground up.
  • Experience securing large-scale multi-cloud infrastructure.
  • Experience working directly with customer security teams.
  • Bachelor's degree in Computer Science or an equivalent technical discipline.

Technology Stack
Go | Kubernetes | AWS | GCP | Azure | Terraform | Docker | SQL | IAM

Ideal Candidate Profile
The ideal candidate is a software engineer first and a security engineer second — someone who enjoys writing production code while thinking deeply about how software, cloud infrastructure, and security intersect.

This person should have strong infrastructure and platform engineering experience, deep hands-on knowledge of cloud and container security, and the ability to work across AWS, GCP, and Azure environments.

As the first dedicated security hire, this individual will have significant ownership and influence. They should be comfortable defining the security roadmap, establishing engineering practices, building customer-facing security capabilities, and working directly with sophisticated customer security teams.

The ideal candidate will be highly technical, pragmatic, and hands-on, with a strong bias toward building secure systems rather than simply implementing security processes or managing infrastructure.

About HRforGrowth:
HRforGrowth is a full-service HR and talent partner built to support companies that are scaling, transforming, or navigating change. HRFG is globally recognized for delivering quality, speed, and cost-effective talent solutions across every level of the workforce. Through its global talent acquisition practice, HRforGrowth applies world class rigor and precision to identifying exceptional professional and executive talent on behalf of its clients — from temporary staffing to permanent hourly workers through to placing C-suite executives. HRforGrowth is presenting this opportunity in its capacity as the retained search partner and does not serve as the employer of record for this position.

Equal Employment Opportunity:
In its recruiting and search practices, HRforGrowth does not discriminate on the basis of race, color, religion, national origin, age, marital status, physical or mental disability, sex, sexual orientation, gender, or gender identity, and welcomes applications from all qualified individuals. HRforGrowth evaluates and presents candidates to its clients without regard to any protected characteristic.

HRforGrowth endeavors to advise the hiring organization to comply with all applicable federal, state, and local equal employment opportunity laws — including those enforced by the U.S. Equal Employment Opportunity Commission (EEOC) — in its hiring decisions, terms of employment, and workplace practices.

Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

To comply with government Equal Employment Opportunity and/or Affirmative Action reporting regulations, we are requesting (but NOT requiring) that you enter this personal data. This information will not be used in connection with any employment decisions, and will be used solely as permitted by state and federal law. Your voluntary cooperation would be appreciated. Learn more.

Invitation for Job Applicants to Self-Identify as a U.S. Veteran
  • A “disabled veteran” is one of the following:
    • a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
    • a person who was discharged or released from active duty because of a service-connected disability.
  • A “recently separated veteran” means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.
  • An “active duty wartime or campaign badge veteran” means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
  • An “Armed forces service medal veteran” means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.
Veteran status



Voluntary Self-Identification of Disability
Voluntary Self-Identification of Disability Form CC-305
OMB Control Number 1250-0005
Expires 07/31/2029
Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Please check one of the boxes below:

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

You must enter your name and date
Human Check*